Junglewise Threat Intelligence

CVE-2026-81098: Telnyx MCP server unauthenticated credential exposure

CVE-2026-81098 · Severity: critical · CVSS 9.1 · Published 2026-08-27

Executive brief

The Telnyx MCP (Model Context Protocol) server, used to integrate Telnyx API services with AI applications, was exposed on all network interfaces without requiring authentication. An unauthenticated attacker could access the server and trigger API calls using the server's stored credentials (Telnyx API key, client secret, and code-execution key), effectively hijacking the server's identity to make unauthorized API requests or execute code.

Technical details

The vulnerability is an authentication bypass in packages/mcp-server/src/http.ts. The HTTP transport was bound to all interfaces (0.0.0.0) instead of loopback, and the server parsed caller authentication headers in a permissive mode that allowed requests without credentials to proceed and dispatch tool calls. When requests were forwarded to the upstream Telnyx endpoint, the server automatically included its own stored credentials (API key, client secret, and code-execution key), allowing any network-accessible attacker to impersonate the server and perform API operations. The fix defaults the host to loopback, requires a server API key, and enforces it via middleware.

Affected products

  • Telnyx telnyx-node before fix in 2026
  • Telnyx MCP server before 6.83.0

Timeline

  • 2026-08-27: disclosed: CVE-2026-81098 published to NVD

References